Oval Definition:oval:com.ubuntu.precise:def:20137106000
Revision Date:2014-01-15Version:1
Title:CVE-2013-7106 on Ubuntu 12.04 LTS (precise) - medium.
Description:Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the (1) display_nav_table, (2) page_limit_selector, (3) print_export_link, or (4) page_num_selector function in cgi/cgiutils.c; (5) status_page_num_selector function in cgi/status.c; or (6) display_command_expansion function in cgi/config.c. NOTE: this can be exploited without authentication by leveraging CVE-2013-7107.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2013-7106
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'icinga' package in precise is affected and needs fixing.
  • BACK